Compliance decisions
GLBA checks for AI vendors
For an institution covered by the FTC Safeguards Rule, an AI vendor receiving customer information belongs in the relevant service-provider review. Assess its ability to safeguard that information, require appropriate safeguards by contract and periodically reassess the provider. A product label does not establish those facts.
For Qualified Individuals, financial-services security and procurement teams
The service-provider duty continues after the first procurement review.
Synthetic institution and procurement case. No real provider approval, contract or safeguards test is represented.01
Confirm the rule and information in scope
The FTC Safeguards Rule applies to financial institutions within its jurisdiction, using a definition broader than everyday use of the word bank. Determine whether the organisation and activity are covered. Do not apply the FTC rule indiscriminately to every business or assume all financial institutions have the same regulator.
Customer information includes records containing nonpublic personal information handled or maintained by or on behalf of the institution or its affiliates. The FTC guidance also addresses information supplied by other financial institutions. A support excerpt or uploaded spreadsheet can contain customer information even when its filename does not identify it as a financial record.
Source context: FTC: Safeguards Rule, what your business needs to know · 16 CFR 314.2: Definitions
02
Identify the service provider and data flow
Map the proposed task, information categories, AI service and any connected recipients. Determine which entity actually handles the information and whether a reseller, application operator or security intermediary has a separate role. Review the exact service and configuration, not only the supplier’s company-level reputation.
The example below concerns a fictional tax-preparation business evaluating AI wording assistance. It initially proposes uploading complete client documents but can achieve the first task using generic descriptions. This is a teaching scenario, not a conclusion that any named vendor is suitable for customer information.
Source context: FTC: Safeguards Rule, what your business needs to know · 16 CFR 314.2: Definitions
03
Connect capability, contract and monitoring
Paragraph 314.4(f) requires reasonable steps to select and retain service providers capable of appropriate safeguards, contractual requirements to implement and maintain them, and periodic assessment based on risk and continuing adequacy. Keep those three questions separate in the evidence record.
Ask for relevant service-specific information about access, security, retention, incident handling and onward processing. Tie the evidence to the actual customer-data task and record gaps. An assurance report can inform the review, but it does not answer every contractual or operational question by itself.
Source context: 16 CFR 314.4: Information-security programme elements
04
Keep the institution’s accountability clear
The Safeguards programme has a designated Qualified Individual, with arrangements appropriate to the institution. Purchasing a tool does not transfer the institution’s responsibilities to the vendor. Procurement, security and the business owner need defined roles for the decision and subsequent changes.
The rule has exemptions from certain provisions for institutions maintaining information concerning fewer than 5,000 consumers. That is not a blanket exemption from all safeguards or an invitation to skip the applicable provider review. Determine the exact provision and scope rather than using company size as a universal shortcut.
Source context: FTC: Safeguards Rule, what your business needs to know · 16 CFR 314.4: Information-security programme elements
05
Reassess when the service changes
Changes to an enabled feature, subprovider, processing location, data category or access model can alter the original review. Record which events trigger a fresh assessment and who tracks them. Periodic review should examine continued suitability, not simply renew the subscription.
Use synthetic records to verify the intended staff input boundary before real customer information is introduced. Keep technical observations alongside, but distinct from, contract and governance evidence. A successful test on one input path does not establish compliance of the entire service or information-security programme.
Source context: 16 CFR 314.4: Information-security programme elements
Put it into practice
AI service-provider oversight example
A fictional tax-preparation firm evaluates a limited wording task before permitting customer documents. Each finding leads to a specific evidence action.
Synthetic institution and procurement case. No real provider approval, contract or safeguards test is represented.
Select
Can the provider safeguard this information?
Contract
What obligations apply to the actual service?
Reassess
Are the safeguards still adequate as risk changes?
| Review area | Illustrative finding | Evidence action |
|---|---|---|
| Institution and information | Fictional covered tax-preparation firm; source files contain nonpublic client information. | Compliance owner confirms actual scope and data categories. |
| Necessity | Generic wording help does not require complete tax returns. | Business owner selects an invented or reduced-context first task. |
| Provider capability | Service-specific handling and safeguards have not been assessed in the scenario. | Security requests evidence relevant to the exact service and data flow. |
| Contract | Appropriate safeguards must be reflected in the applicable agreement. | Procurement records the actual obligations and unresolved terms. |
| Monitoring | No monitoring arrangement exists in the fictional starting proposal. | Assign a provider owner, review cadence and change triggers. |
| Test and decision | No live customer-data use or control test is authorised by the exercise. | Use synthetic material; record actual results and the accountable decision separately. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
glba-ai-provider-oversight.mdInspect
# AI service-provider oversight example
Synthetic institution and procurement case. No real provider approval, contract or safeguards test is represented.
A fictional tax-preparation firm evaluates a limited wording task before permitting customer documents. Each finding leads to a specific evidence action.
| Review area | Illustrative finding | Evidence action |
| --- | --- | --- |
| Institution and information | Fictional covered tax-preparation firm; source files contain nonpublic client information. | Compliance owner confirms actual scope and data categories. |
| Necessity | Generic wording help does not require complete tax returns. | Business owner selects an invented or reduced-context first task. |
| Provider capability | Service-specific handling and safeguards have not been assessed in the scenario. | Security requests evidence relevant to the exact service and data flow. |
| Contract | Appropriate safeguards must be reflected in the applicable agreement. | Procurement records the actual obligations and unresolved terms. |
| Monitoring | No monitoring arrangement exists in the fictional starting proposal. | Assign a provider owner, review cadence and change triggers. |
| Test and decision | No live customer-data use or control test is authorised by the exercise. | Use synthetic material; record actual results and the accountable decision separately. |
## Review steps
- Confirm applicable coverage: Identify the institution, customer-information categories and relevant provider role.
- Match safeguards to the task: Review capability evidence, contractual requirements and ongoing assessment as three separate checks.
- Name the continuing owner: Record who responds to service changes, incidents and periodic reassessment findings.
## Safe example task
“Improve the wording of a generic message telling a client how to arrange an appointment. Do not invent names, income, tax identifiers or account information.”
## Example disposition
Proceed only with the invented wording exercise. The customer-document proposal remains outside this teaching decision. Actual service terms, controls and accountable review must be established for any real customer-information use.
## Source and scope
Guide: https://aona.ai/resources/guides/glba-ai-vendor-safeguards-review/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- FTC: Safeguards Rule, what your business needs to know: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
- 16 CFR 314.2: Definitions: https://www.law.cornell.edu/cfr/text/16/314.2
- 16 CFR 314.4: Information-security programme elements: https://www.law.cornell.edu/cfr/text/16/314.4
Download glba-ai-provider-oversight.mdglba-ai-provider-oversight.csvInspect
Review area,Illustrative finding,Evidence action
Institution and information,Fictional covered tax-preparation firm; source files contain nonpublic client information.,Compliance owner confirms actual scope and data categories.
Necessity,Generic wording help does not require complete tax returns.,Business owner selects an invented or reduced-context first task.
Provider capability,Service-specific handling and safeguards have not been assessed in the scenario.,Security requests evidence relevant to the exact service and data flow.
Contract,Appropriate safeguards must be reflected in the applicable agreement.,Procurement records the actual obligations and unresolved terms.
Monitoring,No monitoring arrangement exists in the fictional starting proposal.,"Assign a provider owner, review cadence and change triggers."
Test and decision,No live customer-data use or control test is authorised by the exercise.,Use synthetic material; record actual results and the accountable decision separately.
Download glba-ai-provider-oversight.csvBefore you proceed
Keep these distinctions clear
- Small does not mean exempt from everything
- Apply any exemption to its specified provisions and facts.
- One report does not close every question
- Match evidence to the actual service, contract and customer-data use.
Apply it to employee AI use
Bring your actual data path.
Aona can support evaluation of employee-AI visibility and sensitive-input policies on supported installed paths.
It is not the institution’s Qualified Individual or an automatic vendor-risk approval system. Its own handling requires review where relevant.
Use the invented client-message task to agree a permitted input and verify the selected path’s policy behaviour.
Review your use caseFAQ
Questions for this decision
Does the FTC Safeguards Rule apply only to banks?
Is a vendor’s security certificate enough?
Do fewer than 5,000 consumers remove all obligations?
Can the AI vendor become our Qualified Individual automatically?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- FTC: Safeguards Rule, what your business needs to know
Covered institutions, customer information, service-provider oversight and the notification threshold and process.
regulator · checked 2026-09-21 - 16 CFR 314.2: Definitions
Customer information, financial-institution scope and the definition and acquisition presumption for a notification event.
law · checked 2026-09-21 - 16 CFR 314.4: Information-security programme elements
Service-provider oversight under paragraph (f) and FTC notification timing, content and discovery under paragraph (j).
law · checked 2026-09-21